summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorShixiong Ou <oushixiong@kylinos.cn>2026-07-29 16:45:17 +0800
committerJocelyn Falempe <jfalempe@redhat.com>2026-08-13 15:47:50 +0200
commit60baa179ed1333535f6e2da4133511db55278ee4 (patch)
treee9e9469dc9dc9af56822a75b7c6bd9598b3c53f5
parent921ac6cb066d09b5765db892d0db0ffaffa98767 (diff)
drm/log: Fix out-of-bounds read on empty message length
drm_log_draw_kmsg_record() accesses s[len - 1] to strip the trailing newline, but len is unsigned int. If len is 0, the subtraction wraps to UINT_MAX, causing an out-of-bounds read. Add an early return when len is 0. Fixes: 25e2c2a3eff5 ("drm/log: Color the timestamp, to improve readability") Signed-off-by: Shixiong Ou <oushixiong@kylinos.cn> Reviewed-by: Jocelyn Falempe <jfalempe@redhat.com> Link: https://patch.msgid.link/20260729084520.688087-1-oushixiong1025@163.com Signed-off-by: Jocelyn Falempe <jfalempe@redhat.com>
-rw-r--r--drivers/gpu/drm/clients/drm_log.c3
1 files changed, 3 insertions, 0 deletions
diff --git a/drivers/gpu/drm/clients/drm_log.c b/drivers/gpu/drm/clients/drm_log.c
index a3259b8f2333..f23a92f826c9 100644
--- a/drivers/gpu/drm/clients/drm_log.c
+++ b/drivers/gpu/drm/clients/drm_log.c
@@ -160,6 +160,9 @@ static void drm_log_draw_kmsg_record(struct drm_log_scanout *scanout,
{
u32 prefix_len = 0;
+ if (!len)
+ return;
+
if (len > TS_PREFIX_LEN && s[0] == '[' && s[6] == '.' && s[TS_PREFIX_LEN] == ']')
prefix_len = TS_PREFIX_LEN + 1;